Re: [OAUTH-WG] Comments on -18

2011-07-25 Thread Torsten Lodderstedt
ok Am 25.07.2011 11:53, schrieb Eran Hammer-Lahav: -Original Message- From: Torsten Lodderstedt [mailto:tors...@lodderstedt.net] Sent: Monday, July 25, 2011 7:24 AM To: Eran Hammer-Lahav Cc: OAuth WG Subject: Re: [OAUTH-WG] Comments on -18 Hi Eran, section 5.2 "The authoriz

Re: [OAUTH-WG] Comments on -18

2011-07-25 Thread Eran Hammer-Lahav
> -Original Message- > From: Torsten Lodderstedt [mailto:tors...@lodderstedt.net] > Sent: Monday, July 25, 2011 7:24 AM > To: Eran Hammer-Lahav > Cc: OAuth WG > Subject: Re: [OAUTH-WG] Comments on -18 > > Hi Eran, > >> section 5.2 > >> > &g

Re: [OAUTH-WG] Comments on -18

2011-07-25 Thread Torsten Lodderstedt
Hi Eran, section 5.2 "The authorization server MAY return an HTTP 401 (Unauthorized) status code to indicate which HTTP authentication schemes are supported." Given the usage of HTTP authentication schemes is the way to authenticated client recommended by the s

Re: [OAUTH-WG] Comments on -18

2011-07-25 Thread Eran Hammer-Lahav
> -Original Message- > From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf > Of Torsten Lodderstedt > Sent: Wednesday, July 20, 2011 2:49 PM > To: OAuth WG > Subject: [OAUTH-WG] Comments on -18 > > section 1.5 > > "(A) The client requests an access token by authentic